Framework overlap

Does NIST SP 1800-32 cover IEC 62304:2015 Medical Device Software Lifecycle Processes?

You hold NIST SP 1800-32 and have been told to do IEC 62304:2015 Medical Device Software Lifecycle Processes. Here is how much overlaps, control by control.

27% of IEC 62304:2015 Medical Device Software Lifecycle Processes you already have

NIST SP 1800-32 already covers about 27% of IEC 62304:2015 Medical Device Software Lifecycle Processes, leaving 24 of 33 controls as genuinely new work.

Already covered 5 Likely covered 4 New work 24

What is genuinely new work

Nothing in NIST SP 1800-32 reaches these. This is the list to scope.

IEC62304-4.2
Risk Management
IEC62304-4.3
Software Safety Classification
IEC62304-4.4
Legacy Software
IEC62304-5.1.1
Software Development Plan
IEC62304-5.1.6
SOUP Identification
IEC62304-5.4
Software Detailed Design
IEC62304-5.5
Software Unit Implementation and Verification
IEC62304-5.6
Software Integration and Testing
IEC62304-5.7
Software System Testing
IEC62304-5.8
Software Release
IEC62304-6.1
Software Maintenance Plan
IEC62304-6.2
Problem and Modification Analysis
IEC62304-6.3
Modification Implementation
IEC62304-7.1
Risk Analysis of Software Contributing to Hazardous Situations
IEC62304-7.3
Verification of Risk Control Measures
IEC62304-8.1
Configuration Identification
IEC62304-8.3
Configuration Status Accounting
IEC62304-9
Software Problem Resolution Process
IEC62304-9.1
Prepare Problem Reports
IEC62304-9.2
Investigate the Problem
IEC62304-9.3
Advise Relevant Parties
IEC62304-9.5
Maintain Records
IEC62304-9.7
Verify Software Problem Resolution
IEC62304-9.8
Test Documentation
Show the 9 you already have
IEC62304-4.1
Quality Management System
IEC62304-5.1
Software Development Planning
IEC62304-7.4
Risk Management of Software Changes
IEC62304-8.2
Change Control
IEC62304-9.4
Use Change Control Process
IEC62304-5.2
Software Requirements Analysis
IEC62304-5.3
Software Architectural Design
IEC62304-7.2
Risk Control Measures
IEC62304-9.6
Analyze Problems for Trends

How this is calculated

Already covered means a mapping runs from a control in NIST SP 1800-32 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition